HTTP Client Vulnerability in Axios Affects Multiple Versions
CVE-2026-101906

8.2HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101906?

Axios, a promise-based HTTP client used in both browser and Node.js environments, is susceptible to a denial of service through a crafted redirect. A flaw in the handling of the HTTP_PROXY or HTTPS_PROXY environment variables when no_proxy is non-empty allows malicious actors to exploit the hostname processing. This occurs when redirect locations with an excessive number of trailing dots cause quadratic backtracking in regular expression processing, potentially blocking the Node.js event loop. This vulnerability impacts all versions from 1.15.0 to 1.20.0, and users are encouraged to upgrade to the patched version 1.20.0 to mitigate the risk.

Affected Version(s)

axios >= 1.15.0, < 1.20.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.